
PoC for testing CVE-2025-29927 for Next.js versions 11.x, 12.x <= 12.3.5, 13.x <= 13.5.9, 14.x <=14.2.25, 15.x <= 15.2.3
This repository contains a minimal Proof of Concept (PoC) for exploiting CVE-2025-29927, a high-severity vulnerability affecting specific versions of Next.js that allows unauthorized access to internal application files through crafted URLs.
This code is intended for educational and authorized security research only. Do not use it on systems you do not own or have explicit permission to test.
git clone https://github.com/liamromanis101/CVE-2025-29927-NextJS
cd CVE-2025-29927-NextJS
python3 cbe-2025-29927.py <url>
